caching AD login credentials not working with 10.5.5
We are trying to add our Mac clients running OSX 10.5.5 as workstations in our Windows Domain (we are running AD in Windows 2003 native mode). I can add the Mac workstation to authenticate against the domain but login will only work if the Mac client is connected to our network.
On a Windows laptop that is a member of the domain, if you are off the network and it can't reach a domain controller it will used cached credentials.
I read that this should work in chapter 6 titled "Active Directory Integration" in the document linked off of Apple's site named "Leveraging Active Directory on a Mac OS X".
Here is the link to that doc http://www.bombich.com/mactips/activedir.html
Here are the steps I followed to add the Mac client to the domain.
1. On the Mac go to "Applications" --> "Utilities"
--> "Directory Utility".
2. Click on "Services" and check off the Active Directory
plugin.
3. Double click the Active Directory plugin and enter in the
following
"Active Directory Forest:" Leave as default
"Active Directory Domain:" wheatonma.edu
"Computer ID:" computername_here
View the Advanced Options and enter in the following.
Under "User Experience" check the "force local home directory on startup disk" option.
I selected the Create mobile account at logon field so that Mac users can logon
with cached credentials when they can't reach a domain controller or are away from the network.
I deselected the Require Confirmation field, because I want all the Mac users on this machine
to use mobile accounts.
Also uncheck the next option "Use UNC path from Active Directory to derive network home location"
Also uncheck the "Default user shell".
Under the "Mappings" tab check off "Map UID to attribute" and change the attribute to "sAMAccountName".
Under the "Administrative" tab uncheck the option "Prefer this domain server".
Also under this tab make sure the "Allow Administration by:" option is checked
off and the following 3 entries should be added (along with the new owner of the mac)
WC\domain admins
WC\enterprise admins
WC\bgibson
Click "Bind" and it will ask you for the local admin's password, enter it.
It will then ask you for the following
Username: Enter in the domain admin username
Password: Active Directory password for the user above.
Computer OU: ou=wheaton macintoshclients,dc=wheatonma,dc=edu
Check off the option named "use for authentication" and uncheck the "use for contacts". Hit "OK".
4. Exit out of the Directory Utility and reboot the computer. Login using the "other" name
and enter in your domain username and Active Directory password.
We do not want to setup an Open Directory and sync data from our domain controllers. All we really need is the ability for the Mac client to authenticate into the system.
Thanks
MacBook, Mac OS X (10.5)